Doing that right now is monumentally difficult. I built an entire CLI app just for solving the "issue AWS credentials that can only access this specific bucket" problem, but I really don't want to have to talk my users through installing and running something like that: https://s3-credentials.readthedocs.io/en/stable/
It really is such a shame that all the projects that tried/are trying to create data sovereignty for users became weird crypto.
Apple actually already does this with iCloud storage but hides it really well so it feels seamless.
https://docs.aws.amazon.com/cognito/latest/developerguide/co...
edit: I think I misread your comment. I understood it as your app wanting to delegate access to a user's data to the client, but it seems like you want the user to delegate access to their own data to your app? Different use-cases.